Legal

Privacy Policy

Last updated: 22 July 2026

This Privacy Policy explains how RentFiles collects, uses, stores, shares, and protects personal information.

RentFiles is operated by GAZEL CHARLES, entrepreneur individuel (SIRET 884 213 489 00013), trading as RentFiles. The data controller is GAZEL CHARLES, entrepreneur individuel, France.

Contact:
Privacy: support@rentfiles.uk
Support: support@rentfiles.uk
Address: 18 avenue des Tournesols, 31490 Léguevin, France

1. What personal information we collect

Depending on how you use RentFiles, we may collect:

Account and contact information

  • name;
  • email address;
  • country, city, or region;
  • support messages.

Rental application information

  • rental preferences;
  • applicant details;
  • employment or income information;
  • rental history;
  • references;
  • household or co-applicant details;
  • supporting evidence details;
  • information you choose to include in your PDF.

Payment and purchase information

  • checkout session ID;
  • payment status;
  • purchase amount;
  • currency;
  • product or pack purchased;
  • payment provider confirmation.

We do not store full card numbers. Payments are processed by Stripe or another payment provider.

Technical and usage information

  • IP address;
  • browser and device information;
  • pages visited;
  • checkout and PDF access events;
  • error logs;
  • security logs;
  • analytics events.

Documents and uploads

If upload features are enabled, we may process files or file metadata that you upload. Do not upload documents you do not have the right to use.

2. How we collect personal information

We collect information:

  • directly from you when you fill in forms;
  • when you generate or download a PDF;
  • when you contact support;
  • when you complete checkout;
  • automatically through security logs, cookies, analytics, and server logs;
  • from payment providers confirming whether payment succeeded.

3. Why we use personal information

Provide the service

  • create your rental application PDF;
  • save progress or tokens where supported;
  • deliver paid downloads;
  • recover purchases;
  • provide customer support.

Process payments

  • create checkout sessions;
  • confirm payment status;
  • prevent unpaid access;
  • handle refunds or disputes.

Protect the service

  • prevent fraud;
  • detect abuse;
  • secure PDF access;
  • rate-limit sensitive routes;
  • debug errors.

Improve the product

  • understand checkout conversion;
  • measure PDF downloads;
  • improve reliability and usability.

Comply with legal obligations

  • tax, accounting, dispute, fraud prevention, and legal compliance.

Marketing

We only send marketing emails if you have consented where required. Transactional emails, such as purchase confirmation or support replies, are not marketing emails.

4. Legal bases where applicable

Where UK GDPR or similar laws apply, we rely on:

Contract

  • generating your PDF;
  • processing your purchase;
  • delivering paid access;
  • providing support.

Legitimate interests

  • securing the service;
  • preventing fraud;
  • improving reliability;
  • measuring basic product performance.

Consent

  • optional marketing emails;
  • non-essential cookies or analytics where consent is required.

Legal obligation

  • accounting, tax, compliance, dispute handling, and lawful requests.

5. Who we share personal information with

We may share limited personal information with service providers that help operate RentFiles, such as:

  • payment processors, including Stripe;
  • hosting providers, such as Vercel or equivalent;
  • database/storage providers, such as Supabase or equivalent;
  • analytics providers, such as PostHog or equivalent;
  • email providers, such as Resend;
  • support and security tools;
  • professional advisers if required;
  • authorities if legally required.

We do not sell your rental application information.

If we ever use advertising or marketing tools that involve “sale” or “sharing” under California privacy law, we will update this policy and provide required choices.

6. Where your data is stored (international transfers)

We have verified that the primary Supabase project used for application details and uploaded documents runs in the Asia-Pacific (Mumbai) region in India. This is outside the United Kingdom and Australia. For UK users, storing and processing this information in India is an international transfer. For Australian users, it is a cross-border disclosure under Australian Privacy Principle 8.

Other service providers (for example payment, analytics, email, and error monitoring) may also process information in the United States, United Kingdom, European Union, or other countries where they operate. Contact us for current information about the applicable contractual transfer safeguards. This policy does not claim a backup or replica location that has not been independently verified.

7. How long we keep information

We keep personal information only as long as needed for the purposes described in this policy.

Typical periods:

  • application-linked uploads and applicant details: automatically deleted 90 days after your last export. Documents saved separately in your account library remain until you remove them, use “Delete my data now”, or delete your account;
  • unpaid or incomplete application tokens: 72 hours from creation;
  • paid transaction records (payment status, checkout session, amount): retained for accounting, tax, and dispute purposes as required by law — these are kept even after your documents and applicant details are deleted;
  • support messages: 24 months;
  • security logs: 12 months;
  • analytics events: 24 months.

The automatic 90-day deletion runs as a scheduled job for application-linked uploads and applicant personal information while keeping only the payment transaction record. “Delete my data now” also removes account-library files associated with your account.

For guest applications, the deletion control is tied to the browser that created the application by a signed, HttpOnly capability cookie. RentFiles stores only a one-way hash of that random capability with the guest application token. The cookie is not available to page scripts and does not authorise deletion from another browser.

8. Security

We use reasonable technical and organisational measures to protect personal information, including access controls, signed access links, server-side payment checks, and limited operational access. Application data and uploaded documents are held in a private, access-controlled store and are encrypted at rest and in transit by our infrastructure provider.

No online service can guarantee perfect security.

9. Your rights

Depending on your location, you may have rights to:

  • access personal information we hold about you;
  • correct inaccurate information;
  • request deletion;
  • object to certain processing;
  • restrict processing;
  • request portability;
  • withdraw consent where processing is based on consent;
  • complain to a privacy regulator.

Delete your data yourself: the application page includes a “Delete my data now” control that immediately removes your uploaded documents and applicant details, keeping only the payment transaction record. For a guest application, use the same browser that created it so the server can verify the browser-bound deletion capability.

To make any other request, contact: support@rentfiles.uk

We may need to verify your identity before acting on a request.

10. California privacy notice

If California privacy law applies to RentFiles, California residents may have rights to know, delete, correct, and limit certain uses of personal information.

Categories we may collect:

  • identifiers;
  • customer records;
  • commercial information;
  • internet or network activity;
  • geolocation at city/country level where inferred;
  • user-generated application content.

Purposes:

  • service delivery;
  • payment;
  • security;
  • support;
  • analytics;
  • legal compliance.

We do not knowingly sell personal information.

11. Canada privacy notice

For Canadian users, RentFiles aims to collect, use, and disclose personal information only for understandable and identified purposes.

We request meaningful consent where required and provide this policy so users can understand what is collected, why, and what may happen if they use the service.

12. Australia privacy notice

For Australian users, RentFiles aims to handle personal information in line with open and transparent privacy practices.

You may request access or correction by contacting: support@rentfiles.uk

13. UK privacy notice

For UK users, this policy explains:

  • who we are;
  • what we collect;
  • why we use it;
  • lawful bases;
  • retention;
  • sharing;
  • international transfers;
  • your rights.

You may have the right to complain to the UK Information Commissioner’s Office.

14. Cookies and analytics

We use essential cookies or similar technologies to operate the service, secure access, and process checkout.

Browser product analytics are non-essential and disabled by default in every RentFiles market. We initialise browser PostHog and create analytics attribution storage only after you choose “Allow analytics”. Declining does not limit the service.

Independently of that browser choice, we record a minimal set of pseudonymous server-side checkout lifecycle events to protect checkout and monitor payment reliability. We use those events for our legitimate interests in operating and securing the paid service. They contain opaque transaction or session identifiers and payment-state facts, not application answers, uploaded files, contact details, or browser interaction data; they do not enable session recording or browser tracking.

We use privacy-limited, pseudonymous events to understand product performance. Session recording and automatic interaction capture are disabled. We do not send application form answers, uploaded documents, calculator values or results, generated letters, pet details, or other Tool output to analytics.

After opt-in, the analytics identifier and acquisition attribution use same-tab session storage. Your allow or decline choice is stored separately for up to six months. That preference record contains only the choice and time; remembering a refusal is necessary to honour it and avoid asking on every page. If browser storage is unavailable, the choice applies to the current page only.

A Tool result that you explicitly ask to review in an application may use separate, short-lived same-tab storage to perform that requested handoff. It is functional application state, not analytics, and does not enable PostHog.

You can allow, decline, or withdraw analytics consent at any time.

15. Children

RentFiles is not intended for children. You must be at least 18 years old, or the age of majority in your location, to purchase or use RentFiles.

16. Changes to this policy

We may update this policy from time to time. The latest version will be posted on this page.

17. Contact

Privacy questions: support@rentfiles.uk
Support: support@rentfiles.uk